Showing posts with label DejaBlue. Show all posts
Showing posts with label DejaBlue. Show all posts

Saturday, November 2, 2019

Public ICS Disclosures – Week of 10-26-19


This week we have four vendor disclosures from Phoenix Contact, ABB, Johnson Controls, and BD. There are three vendor updates from 3S, Yokogawa, and Belden. There are also three exploit reports from researchers for products from Carel and Intelligent Security Systems. The later may be a 0-day exploit.

Phoenix Contact Advisory


Phoenix Contact published an advisory [.PDF download link] describing an unauthorized access vulnerability in their FL NAT industrial ethernet switch/router. The vulnerability is self-reported. Phoenix Contact provides generic mitigation measures pending the development of new firmware.

ABB Advisory


ABB published an advisory describing an authentication bypass vulnerability in their Power Generation
Information Manager. The vulnerability was reported by Rikard Bodforss at CS3STHLM. ABB has a new version that mitigates the vulnerability. Bodforss has verified the efficacy of the fix.

NOTE: The disclosure blog post by Bodforss has an excellent discussion about the vulnerability disclosure dilemma from the viewpoint of a researchers. Well worth reading.

Johnson Controls Advisory


Johnson Controls has published an advisory describing two vulnerabilities in their FX Supervisory Controller. The vulnerabilities were reported in the third-party QNX operating system. Johnson Controls has patches to mitigate the vulnerability and a new version to be released later this month will fully address the problems.

The two reported vulnerabilities are:

• Information exposure - CVE-2019-8998; and
• Improper authorization - CVE-2019-13528

NOTE 1: I wonder if NCCIC-ICS will update their Tridium advisory to provide a link to this advisory? Nah.

NOTE 2: Just another case of wondering what other vendors use the same vulnerable operating system?

BD Advisory


BD has published an advisory for the DejaBlue remote desktop vulnerabilities in their products. BD has provided generic work arounds while it continues to test and validate the Microsoft patch for BD products.

3S Update


3S published an update of their CODESYS ENI server advisory that was originally published on September 12, 2019. The new information includes:

Additional mitigation measure;
Mitigated version updated; and
CVE added

Yokogawa Update


Yokogawa published an update of their unquoted service path advisory that was originally published on September 27th, 2019 and most recently updated on October 24th. The new information is another change to the Exaquantum mitigation.

Belden Update


Belden published an update of their URGENT/11 advisory that was originally published on July 11th, 2019 and most recently updated on September 5th. The new information includes updated mitigation information for their EAGLE and EAGLE one products.

Carel Exploits


Red Team Pentesting published exploit code for an unsafe storage of credentials vulnerability in the Carel pCOWeb card. This vulnerability was previously reported in the Rittal Chiller using the pCOWeb card. Red Team Pentesting reports that Carel consideres this product obsolete and no longer provides updates for the firmware.

Red Team Pentesting published exploit code for an unauthenticated access to modbus interface vulnerability in the Carel pCOWeb card. This vulnerability was previously reported in the Rittal Chiller using the pCOWeb card. Red Team Pentesting reports that Carel consideres this product obsolete and no longer provides updates for the firmware.

Intelligent Security System Exploit


Alberto Vargas published exploit code for an unquoted service path vulnerability in the Intelligent Security System SecurOS Enterprise. There is no indication that this disclosure was coordinated with the vendor so this may be a 0-day exploit.

Saturday, September 28, 2019

Public ICS Disclosures – Week of 09-21-19


This week we have four vendor disclosures for products from ABB, Schneider, Sick, and Yokogawa  and one vendor update for products from Schneider.

ABB Advisory


ABB published an advisory reporting that two of the Wind River URGENT/11 vulnerabilities affected their AC 800M controllers. ABB provides generic work arounds while it is working on new versions to mitigate the vulnerabilities.

Schneider Advisory


Schneider published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in a list of Schneider products. Schneider recommends applying the appropriate Windows updates for some products and provides generic workarounds for others.

Schneider Update


Schneider published an update for their advisory on the effect of the BlueKeep {Microsoft® RDP vulnerability (CVE-2019-0708)} on a list of their products. They added “Conext Control” to list of affected products.

Sick Advisory


Sick published an advisory describing a buffer overflow vulnerability in the Sick FX0-GENT00000 and FX0-GPNT00000 safety controllers. The vulnerability was reported by the security-testlab team of Fraunhofer IOSB. Sick has a new firmware version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

Yokogawa Advisory


Yokogawa published an advisory describing an unquoted service path vulnerability in a list of their products. This vulnerability is self-reported. Yokogawa has new versions and patches to mitigate the vulnerability.

Saturday, September 14, 2019

Public ICS Disclosures – Week of 09-07-19


This week we have 11 vendor disclosures for products from Siemens (3), Schneider (3), Bosch (2), 3S, Eaton, and Draeger. We also have 3 vendor updates from Schneider (2) and Siemens.

Siemens Advisories


DejaBlue Advisory

Siemens published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in the Siemens Healthineers Products. In most of the affected products Siemens is recommending applying the appropriate MS patches.

Siemens repeatedly makes the following observation: “The compatibility of Microsoft security patches with products from Siemens Healthineers that are beyond their End of Support date cannot be guaranteed.”

RUGGEDCOM URGENT/11 Advisory

Siemens published an advisory describing the Wind River URGENT/11 vulnerabilities in the Siemens RUGGEDCOM Win base stations. Siemens provides generic workarounds for the vulnerabilities.

SINEMA Advisory

Siemens published an advisory describing four vulnerabilities in the Siemens r SINEMA Remote Connect Server. The vulnerabilities were reported by Hendrik Derre and Tijl Deneut from HOWEST. Siemens has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

Password guessing - CVE-2019-13918;
Privilege escalation - CVE-2019-13919;
Cross-site request forgery - CVE-2019-13920; and
Password hash - CVE-2019-13922

Siemens Update


Siemens published an update for an advisory that was originally published on June 9th, 2019. This update provides corrected version information and mitigation information for:

FieldPG M4;
FieldPG M5; and
ITP1000

Schneider Advisories


U.Motion Server Advisory

Schneider published an advisory describing six vulnerabilities in the Schneider U.motion din rail and touch panel servers. The vulnerabilities were reported by Zhu Jiaqi and Constantin-Cosmin Craciun. Schneider has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The six reported vulnerabilities are:

Cross-site scripting - CVE-2019-6835;
Improper access control (3) - CVE-2019-6836, CVE-2019-6838 and CVE-2019-6839;
Server-side request forgery - CVE-2019-6837; and
Format string - CVE-2019-6840

Modicon Quantum Advisory

Schneider published an advisory describing an improper check for unusual or exceptional conditions vulnerability for the Schneider Modicon Quantum 140 NOE771x1 controllers. The vulnerability is self-reported. Schneider has a new version that mitigates the vulnerability.

TwidoSuite Advisory

Schneider published an advisory describing two vulnerabilities in the Schneider TwidoSuite product. The vulnerability is self-reported. This product is no longer supported.

The two reported vulnerabilities are:

Untrusted search path;
Input validation

Schneider Updates


BlueKeep Update

Schneider published an update for an advisory that was originally published on July 12, 2019. The update includes:

Exploit information; and
Updated affected product versions

 Floating License Manager Update

Schneider published an update for an advisory that was originally published on May 14th, 2019. The update provides updated affected product information.

Bosch Advisories


Bosch published two advisories (here and here) describing vulnerabilities in the Access Professional access control system. The vulnerabilities were reported by Oleksii Orekhov. Bosch has a new version that mitigates the vulnerabilities. There is no indication that Orekhov has been provided an opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Hard-coded credentials - CVE-2019-11898; and
Improper access control - CVE-2019-11899

3S Advisory


3s published an advisory describing a stack-based buffer overflow vulnerability in the CODESYS V2.3 ENI servers. This vulnerability was reported by Chen Jie from NSFOCUS. 3S has an update that mitigates the vulnerability. There is no indication that Chen has been provided an opportunity to verify the efficacy of the fix.

Eaton Advisory


Eaton published an advisory describing multiple undisclosed vulnerabilities in the Eaton Intelligent Power Protector. The vulnerabilities are apparently self-reported. Eaton has a new version that mitigates the vulnerabilities.

NOTE: Eaton continues to publish unusable security advisories.

Drager Advisory


Drager published an advisory describing the Microsoft Windows® DejaBlue vulnerabilities in Drager products.

Saturday, August 24, 2019

Public ICS Disclosures – Week of 08-17-19


This week we have two vendor disclosures for products from Bosch and Schneider and an update from Schneider.

Bosch Advisory


Bosch published an advisory describing three vulnerabilities in their ProSyst mBS SDK and Bosch IoT Gateway Software. The vulnerabilities are being self-reported. Bosch has new versions that mitigate the vulnerabilities.

The three reported vulnerabilities are:

Path traversal - CVE-2019-11601;
Server-side request forgery - CVE-2019-11897; and
Information exposure through an error message - CVE-2019-11602

Schneider Advisory


Schneider published an advisory for the latest Microsoft® Remote Desktop Services (DejaBlue) vulnerabilities in their products running on machines using various MS operating systems. Generic mitigations are provided. Schneider does provide the following warning about applying the MS patches that should mitigate these vulnerabilities:

“Please note that as of the date of this publication, it is unclear how Microsoft’s patches and updates will affect systems performance. Therefore, customers should proceed with caution when applying these patches to critical operating systems and/or performance-constrained systems. We strongly recommend evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure.”

NOTE: This advisory has already been updated twice.

Schneider Update


Schneider published an update for their advisory on the Wind River VxWorks vulnerabilities in their products. They changed the affected products list by:

Removin Modicon M580 Ethernet / Serial RTU Module; and
Adding Modicon eX80 - BMEAHI0812 HART Analog Input Module

 
/* Use this with templates/template-twocol.html */